2023 CVE Vulnerabilities

31,411 CVEs published in 2023.

CVE IDSeverityCVSSDescription
CVE-2023-28039MEDIUM6.7 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator ...
CVE-2023-28035MEDIUM6.7 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator ...
CVE-2023-28033MEDIUM6.7 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator ...
CVE-2023-28032MEDIUM6.7 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator ...
CVE-2023-28030MEDIUM6.7 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator ...
CVE-2023-28029MEDIUM6.7 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator ...
CVE-2023-28028MEDIUM6.7 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator ...
CVE-2023-25937MEDIUM6.7 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator ...
CVE-2023-25936MEDIUM6.7 Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with administrator ...
CVE-2023-33299CRITICAL9.8A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions ...
CVE-2023-32464LOW3.3 Dell VxRail, versions prior to 7.0.450, contain an improper certificate validation vulnerability. A high privileged rem...
CVE-2023-32463HIGH7.5 Dell VxRail, version(s) 8.0.100 and earlier contain a denial-of-service vulnerability in the upgrade functionality. A r...
CVE-2023-31469HIGH8.8 A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. Th...
CVE-2023-35801HIGH8.1A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation ...
CVE-2023-23344MEDIUM6.5A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an ...
CVE-2023-36193HIGH7.8Gifsicle v1.9.3 was discovered to contain a heap buffer overflow via the ambiguity_error component at /src/clp.c.
CVE-2023-36192HIGH7.8Sngrep v1.6.0 was discovered to contain a heap buffer overflow via the function capture_ws_check_packet at /src/capture....
CVE-2023-36191Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2023-33141HIGH7.5Yet Another Reverse Proxy (YARP) Denial of Service Vulnerability
CVE-2023-34462MEDIUM6.5Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan...
CVE-2023-34241HIGH7.1OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Sta...
CVE-2023-34110LOW2.7Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticate...
CVE-2023-28016MEDIUM6.1Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to s...
CVE-2023-28006HIGH7.8The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.
CVE-2023-3114HIGH7.7Terraform Enterprise since v202207-1 did not properly implement authorization rules for agent pools, allowing the worksp...

Check if your code is affected by 2023 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now